Sign inSign up
Calico Node

dhi.io/calico-node

Calico Node 3.30.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.30-debian-fips, 3.30-debian13-fips, 3.30-fips, 3.30.7-debian-fips, 3.30.7-debian13-fips, 3.30.7-fips, v3.30.7-fips

Index digest:

sha256:a7dd090d8fe5ecea612aa3fb36a9a52a45860037c9cbe6cc1b21e7068a448c31

Manifest digest:

sha256:41dc5c7ef0895fe72d2e8a63e5903738b3f85ba9aca95bf5fdac7cbb16936696

Size

56.32 MB

Last pushed

24 hours ago

Vulnerabilities

0
1
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-node:3.30-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-node:3.30-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-node@sha256:9998d8e5b44e72531c24b86e59f044f75ce5b98a3d5a78be31e2e58d3738a3a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-node@sha256:11d3444d71d78c5119271c3d3b2b5770bafbdaae20968eefebb615b555188ac1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/calico-node@sha256:8594d8dc29bc8a6e9069ecb6899bda84cbc61b93413893a61c16a83b571df0dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-node@sha256:d4ce9613790229e66020afb5ce3a1fe46277deedc373cefaba90dd3a6f64db8b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/calico-node@sha256:255fba04d1cdb9e89507216e22d9d773c050df0dc6b3909f9d6c388f6495e26f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-node@sha256:0bd0d4b43ebfe673a04b31d5bc86981bae525f779418f11008b5447bd1a8a40f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-node@sha256:cbadf5453d4c385c756d1bfba3783fc658ea61fa45d03ab806ab13a0d65b7fe8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-node@sha256:dd508c73358d9c13029b4351350296b65f1950e66babd82981f39f4b1e0489aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-node@sha256:fa3991c1fdfb4caabcd978dc78b9943d45d59f2d810b40b16f74d12751e87c57
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-node@sha256:84fd158e4ee0a5a0f296b7a328bc8396c9e0b47de8eb14cc5e2e1c3b53a39cb9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-node@sha256:54b6a4d94d03c55f8016711f516535353f3b8db5466eb265014a72b341770d59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-node@sha256:1612da8ab292248b1281e8510f50334c7fb74370234a21de5dabda3e2dd47666
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-node@sha256:e5b8b5373c72f4fff736ea749d8bcbe21e02a78daddd5bf835426c2fbcd22837
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-node@sha256:d8dbc85f85f97ebfd1c8b843081992e66e31bbde774ef9e0ab5d3aa11c1407ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-node@sha256:893a67a59bc925b098efc5d994da8727cff742be76f369f51d62f4ccbaf58a8b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-node@sha256:1b749d360c748a3adf4387e61b75ae11b091af7b1d0832dee33a449280c3d620
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-node@sha256:02dee841f59ff7b97e3b35a4e181039c986ec166ed892ec554ed4a7aba109a70